CVE-2026-103534Medium· 6.3▾ SunlitA vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103533Medium· 4.1A vulnerability was found in David-Crty databasement up to 1.7.1
CVE-2026-95654High· 7.4Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance
CVE-2026-101144Medium· 6.3A vulnerability was determined in Eleveo Call Recording Software 9.7.0
CVE-2026-101053High· 7.3A vulnerability was determined in Thinkware U3000 up to 1.02.04
CVE-2026-101054Medium· 5.3A vulnerability was identified in Thinkware U3000 up to 1.02.04
CVE-2026-100883Medium· 6.3A flaw has been found in Krayin laravel-crm up to 2.2.5